CVE-2018-0471 is a memory leak vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2. An unauthenticated, adjacent attacker can exploit this by sending specially crafted CDP packets, leading to continuous memory consumption and ultimately a denial of service (DoS) due to a device crash and reload. With a CVSS score of 7.4 (High), this vulnerability has a low attack complexity and requires no user interaction, but it is limited to adjacent network access. There is no evidence of active exploitation, nor is public exploit code available, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.6.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.1:*:*:*:*:*:*:* | ||
16.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.